Safe harbor authorization
When conducting vulnerability research according to this policy, we consider this research to be authorized. We will work with you to understand and resolve the issue quickly, and YuJa will not initiate or recommend legal action related to your research.
Should legal action be initiated by a third-party against you for activities that were conducted in accordance with this policy, we will make this authorization known. However, please understand that this policy does not and cannot legally bind any third-parties, nor does it authorize testing on third-party infrastructure. You remain responsible for complying with all applicable laws.
Guidelines for good-faith security research
To maintain Safe Harbor protection, researchers must adhere strictly to the following rules of engagement during all testing phases:
Do no harm and maintain availability
Make every effort to avoid privacy violations, degradation of user experience, disruption to production systems, and the destruction or corruption of data. Denial of Service (DoS) testing is strictly prohibited under all circumstances.
Protect confidentiality and PII
Under no circumstances should you access, download, modify, or delete data belonging to YuJa’s clients, students, or institutional partners. If you inadvertently encounter Personally Identifiable Information (PII), personal health information, or data governed by FERPA, GDPR, or HIPAA during your testing, you must immediately halt testing, securely purge any local copies of the data, and report the vulnerability to our team at once.
Limit exploitation
Only utilize exploits to the extent strictly necessary to confirm a vulnerability’s presence. Do not use an exploit to compromise or exfiltrate data, establish persistent command-line access, pivot to other internal systems, or maintain a backdoor.
Coordinated vulnerability disclosure (CVD)
You must not publicly disclose the vulnerability or share details with any third-party without explicit, written permission from the YuJa Inc. security team. You must provide us with a reasonable, agreed-upon timeframe to develop, test, and deploy a remediation patch before any public release of information.
Scope definitions and boundaries
To ensure testing remains productive and safe, YuJa explicitly defines the boundaries of authorized research.
Core web domains (in-scope)
*.yuja.com encompassing all main web properties, authenticated dashboards, and web applications.
Product platforms (in-scope)
YuJa Panorama, YuJa Lumina, YuJa EqualGround, YuJa Verity, and YuJa CivicGuard platforms.
Mobile applications (in-scope)
YuJa enterprise mobile applications deployed on iOS and Android operating systems.
Integration endpoints (in-scope)
YuJa public APIs and Learning Tools Interoperability (LTI 1.3 Advantage) integration endpoints hosted by YuJa.
Volumetric attacks (out-of-scope)
Any form of Denial of Service (DoS), Distributed Denial of Service (DDoS), or resource exhaustion attacks.
Social engineering (out-of-scope)
Phishing, vishing, or smishing attacks directed at YuJa employees, contractors, or client institutions.
Physical security (out-of-scope)
Physical penetration testing of YuJa corporate offices, employee devices, or third-party data centers.
Third-party infrastructure (out-of-scope)
Testing of third-party vendors, cloud providers (e.g., AWS, Google Cloud), or external platform APIs (e.g., Zoom, YouTube) that integrate with YuJa, unless the vulnerability resides strictly within YuJa’s proprietary code implementation.
Reporting mechanics, requirements, and service level agreements
If you believe you have discovered a vulnerability that falls within the scope of this policy, please report it immediately to our dedicated security routing team by emailing the appropriate contact channel.
Contact method: security@yuja.com
Report requirements
To assist our engineering team in verifying and resolving the issue rapidly, please ensure your submission includes:
- A comprehensive description of the vulnerability, including its location (URL or specific endpoint) and the potential impact on system confidentiality, integrity, or availability.
- Detailed, step-by-step technical instructions required to reliably reproduce the vulnerability.
- Proof-of-Concept (PoC) code, scripts, or non-destructive screenshots. (Note: Scripts or exploit code should be embedded into non-executable file types or standard archives such as zip or gzip).
- The exact date and time the vulnerability was initially discovered.
Our commitment and timelines (SLAs)
Upon receipt of a vulnerability report, we commit to the following operational timelines:
- Acknowledgment: We will formally acknowledge receipt of your report within three (3) business days.
- Triage and Assessment: We will provide an initial technical assessment and triage status within ten (10) business days.
- Remediation: We will keep you reasonably informed of the remediation progress and aim to resolve critical vulnerabilities as swiftly as possible, prioritizing issues based on severity and potential impact.